Trust
Security and data
The short version: tools connect through their own sign-in, tokens are encrypted, your data is yours alone, and every change Sands makes is recorded.
Connections and credentials
- Every tool connects through its own sign-in (OAuth). Sands never sees your passwords.
- Tokens are stored encrypted and tied to your account. Sands works with the access you granted, nothing wider.
- Disconnect from Settings at any time, or revoke access from the tool's own settings.
Your data
- Chats, plans, uploads and settings belong to your account. The database enforces that no other account can read them.
- Uploaded files are stored privately; only you can open them.
- Every run keeps its record: what Sands read, what it changed, and what you approved.
- Deleting your account deletes your data and disconnects your tools.
Changes to your tools
- Sands only carries out changes you asked for, on items it can identify.
- Your approval mode decides when Sands asks first. Riskier changes pause by default.
- An approved change runs exactly as approved. If the target or content changed since, it does not run.
- Each change runs once and is read back after it runs.
See Approvals and How Sands works.
Compliance
Sands runs on SOC 2 certified infrastructure; our own SOC 2 program is underway. Ask for current status and you will get a straight answer. More on the security page, or write to hello@sandsai.co.